First published: Fri Apr 12 2024(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in Elementor Hello Elementor.This issue affects Hello Elementor: from n/a through 3.0.0.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Elementor | <=3.0.0 | |
Hello Elementor | <=3.0.0 |
Update to 3.0.1 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-31289 is classified as a Cross-Site Request Forgery (CSRF) vulnerability with a significant risk if exploited.
To fix CVE-2024-31289, update the Hello Elementor theme to version 3.0.1 or later.
CVE-2024-31289 affects Hello Elementor versions from n/a through 3.0.0.
Cross-Site Request Forgery (CSRF) in CVE-2024-31289 allows an attacker to perform unintended actions on behalf of a user without their consent.
If you are unable to update Hello Elementor, consider removing the theme or implementing additional security measures to mitigate the CSRF vulnerability.